Thu Jun 03, 2004 3:13 pm
Did u ever read Reference Manual?
Example
To add a destination NAT rule that gives access to the http server 192.168.0.22 on the local network via
external dynamic address, use the following command:
[admin@MikroTik] ip firewall dst−nat> add action=nat protocol=tcp \
\... dst−address=0.0.0.0/32:80 to−dst−address=192.168.0.22
[admin@MikroTik] ip firewall dst−nat> add action=nat protocol=tcp \
\... dst−address=0.0.0.0/32:20 to−dst−address=192.168.0.22
[admin@MikroTik] ip firewall dst−nat> add action=nat protocol=tcp \
\... dst−address=0.0.0.0/32:21 to−dst−address=192.168.0.22
[admin@MikroTik] ip firewall dst−nat> print
Flags: X − disabled, I − invalid, D − dynamic
0 src−address=0.0.0.0/0:0−65535 in−interface=all
dst−address=0.0.0.0/32:80 protocol=tcp icmp−options=any:any flow=""
connection="" content="" src−mac−address=00:00:00:00:00:00
limit−count=0 limit−burst=0 limit−time=0s action=nat
to−dst−address=192.168.0.22 to−dst−port=0−65535
1 src−address=0.0.0.0/0:0−65535 in−interface=all
dst−address=0.0.0.0/32:20 protocol=tcp icmp−options=any:any flow=""
connection="" content="" src−mac−address=00:00:00:00:00:00
limit−count=0 limit−burst=0 limit−time=0s action=nat
to−dst−address=192.168.0.22 to−dst−port=0−65535
2 src−address=0.0.0.0/0:0−65535 in−interface=all
dst−address=0.0.0.0/32:21 protocol=tcp icmp−options=any:any flow=""
connection="" content="" src−mac−address=00:00:00:00:00:00
limit−count=0 limit−burst=0 limit−time=0s action=nat
to−dst−address=192.168.0.22 to−dst−port=0−65535
[admin@MikroTik] ip firewall dst−nat>